As cited
Copy frozen at (site build).
vulnerabilities
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
A Russian state-backed espionage group exploited a previously unknown vulnerability in Zimbra's webmail client to access email messages, directories, saved passwords, and two-factor authentication recovery codes over a period of months. The malicious payload extracted the last 90 days of emails and required only message opening to execute. U.S. government agencies including NSA (National Security Agency) and CISA (Cybersecurity and Infrastructure Security Agency) subsequently issued guidance on the matter.
Why it matters: Organizations using Zimbra webmail face compromise of email communications and 2FA bypass mechanisms; practitioners should patch immediately and review access logs for suspicious activity.
- Source published
- First seen by Cybersecurity Tracker